
The substrate underneath the other six, and the one nobody ever bought
At 22:00 UTC on 25 January 2016, the United States Air Force removed the oldest satellite in the GPS constellation from service.
It should have been routine.
Instead, a ground software fault introduced an error into the timing message broadcast by several other satellites.
The error was thirteen microseconds.
Thirteen millionths of a second.
Within hours, telecommunications systems in Britain and Sweden were reporting failures. Mobile carriers, transport communications and broadcasting were affected. One major customer found roughly two-thirds of its GPS timing equipment affected, with nearly 2,500 alarms firing across its networks.
Nobody attacked anything.
A satellite was retired as planned.
Software produced the wrong time.
And infrastructure thousands of kilometres away began failing.
That event reveals a dependency most organisations barely recognise.
When most people think about GPS, they think about position.
Critical infrastructure often cares just as much about time.
Electricity grids compare the phase of alternating current across hundreds of kilometres and therefore need clocks agreeing to within microseconds.
Mobile networks synchronise transmissions between base stations.
Distributed databases order events using timestamps.
Financial markets timestamp trades against regulated reference clocks.
Transport, logistics and industrial control systems use precise time to establish the sequence of events across geographically dispersed infrastructure.
This means the six physical substrates examined earlier in Series II share another layer underneath them.
They need a common clock.
The dependency nobody bought
That produces an unusual management problem.
Most infrastructure dependencies have an organisational identity.
A supplier.
A contract.
An invoice.
A budget.
Someone responsible for procurement.
Satellite timing frequently has none.
A GPS receiver may have arrived inside a base station, network switch, industrial controller or protection relay selected years earlier by the manufacturer.
The satellite signal itself costs nothing.
No contract gets renewed.
No supplier asks for payment.
No budget owner needs to approve it.
As a result, the dependency can remain outside almost every conventional risk-management process.
It isn't in the supplier register because there is no supplier.
It isn't reviewed during contract renewal because there is no contract.
It isn't challenged in cost exercises because it has no cost.
And it may survive reorganisations because nothing that belongs to nobody needs to be reassigned.
That is the central finding of this article:
A dependency nobody owns cannot reliably be managed.
The problem becomes more subtle because critical equipment often has its own oscillator.
If satellite timing disappears, that oscillator keeps running.
A modest system may remain accurate for hours.
A better one may hold for days.
At first sight, this looks like resilience.
But it changes the shape of failure.
Instead of an immediate outage, the organisation gets a countdown.
Different devices drift outside their tolerances at different times.
Failures appear gradually.
The common cause becomes less obvious.
Diagnosis becomes harder.
And this protection works mainly when the signal disappears.
It does much less when the system receives a believable but incorrect time.
Jamming and spoofing aren't the same problem
This distinction matters.
Jamming denies the signal.
The equipment knows that its external timing reference has disappeared and can move to holdover.
Spoofing supplies a false signal that the receiver accepts as genuine.
From the receiver's perspective, nothing failed.
That can be more dangerous.
A system told nothing knows it has a problem.
A system confidently told the wrong thing may continue operating incorrectly.
This is why simply adding another satellite constellation isn't necessarily genuine redundancy.
Four global constellations appear diverse.
Physically, however, they remain variations of the same architecture: weak signals arriving from space in nearby frequency bands.
The article's completed seven-row table therefore makes an important distinction: apparent diversity is not necessarily physical diversity. TIC_S2A07_Website_Full
Interference is becoming part of the environment
European aviation provides the clearest public evidence of how quickly the operating environment has changed.
Flights encountering satellite-navigation interference increased from roughly 200 per day in Q1 2024 to around 900 per day in Q2.
Reported signal-loss events increased approximately 220% between 2021 and 2024.
Up to 38% of European en-route traffic now crosses regions intermittently affected by radio-frequency interference.
The hotspots are familiar: the Baltic, eastern Europe, the Black Sea, the eastern Mediterranean and parts of the Middle East.
Yet aviation continues functioning.
That is a success.
It is also a warning.
Aviation has procedures, trained crews, alternative navigation aids, safety bulletins and regulatory monitoring.
The industry has adapted.
But successful adaptation can transform an emergency into a condition.
And conditions become normal.
The deeper risk is therefore not that aviation stops coping.
It is that other sectors look at aviation's competence and assume the underlying infrastructure problem has been solved.
It hasn't.
The technology already exists
This is what makes the situation unusual.
Many infrastructure constraints examined in this series require years of construction, new mines, new factories or difficult political decisions.
Timing is different.
Alternatives already exist.
Terrestrial long-range timing such as eLoran is mature.
Highly accurate time can be distributed through fibre.
Local atomic clocks are commercially available.
Authenticated satellite signals are being deployed.
The substitution problem is therefore comparatively manageable.
So why hasn't the market solved it?
Because the existing service is free.
Because the benefit of resilience is spread across an entire economy while the cost falls on individual equipment owners.
Because failures are rare and difficult to attribute.
And because nobody owns the dependency.
The technology has been waiting for a customer.
The customer often doesn't exist.
Britain shows what happens when the state becomes the buyer
In November 2025, the United Kingdom committed £155 million to national timing resilience.
£71 million went toward eLoran.
£68 million toward a national timing centre.
£13 million toward interference monitoring.
£3 million toward research into space-based time transfer.
The government-cited estimate for a 24-hour satellite-navigation outage is approximately £1.4 billion.
The comparison matters.
A £155 million resilience programme costs less than three hours of the outage it is designed to mitigate, assuming the estimate is approximately correct.
This was never fundamentally an affordability problem.
It was an ownership problem.
For two decades, the dependency accumulated without a natural buyer.
Once the state accepted ownership, the economics looked very different.
What happens next
Our forecasts test whether that ownership begins spreading.
By the end of 2027, we assign a 60% probability that at least one additional G7 or EU government announces a national PNT resilience programme with committed funding of at least €50 million.
By 2029, we assign a 55% probability that at least one national regulator imposes a binding requirement for satellite-independent timing or minimum holdover in power, telecommunications or finance.
By 2031, we assign a 75% probability that European aviation authorities still treat satellite-navigation interference as a routine operational condition.
And over the decade to 2036, we assign a 60% probability that satellite timing failure or denial causes a publicly attributed outage exceeding four hours in a non-aviation critical sector in a G7 country.
The most important variable isn't necessarily whether the outage occurs.
It is whether somebody publicly identifies timing as the cause.
One well-attributed incident could accomplish years of policy change in an afternoon.
What individuals should do
For most people, direct exposure is limited.
But if you work with infrastructure, engineering, networks, trading systems or industrial control, ask one simple question:
Does anything I'm responsible for take its time from a satellite?
You may discover nobody has asked before.
The larger lesson is transferable.
Look for dependencies in your own work that nobody owns because they have never cost anything.
A tool everyone uses.
A source everyone trusts.
A process one person quietly keeps running.
Those are often the dependencies conventional reviews miss.
What businesses should do
Start with an inventory.
Which systems receive satellite timing directly?
Which receive network time that ultimately traces back to a satellite receiver?
How long can each system remain within tolerance if that reference disappears?
What happens when the tolerance expires?
That sequence tells you the order in which systems fail.
Then do something even simpler:
give the dependency an owner.
Put it in someone's job description.
Without ownership, an inventory becomes a document produced once and forgotten.
With ownership, procurement, monitoring and resilience can follow.
And don't prepare only for losing time.
Prepare for wrong time.
Authentication, independent reference sources and alarms for unexpected timing changes address a different failure mode from holdover.
What capital should watch
In this substrate, regulation matters more than technological invention.
The technology has existed for years.
What has been missing is a buyer.
A binding holdover or satellite-independent timing requirement would create that buyer immediately.
That means government programmes, regulatory consultations and equipment standards may lead commercial demand rather than follow it.
There is also a broader pattern emerging from Series II.
Refined-material resilience may require public price support.
Submarine-cable resilience depends partly on repair capacity that earns little while waiting for an incident.
Timing resilience has no natural customer.
In each case, the market underprovides capacity that appears expensive during normal conditions and invaluable during failure.
That is where public capital increasingly enters.
The larger lesson
Series II began by measuring physical infrastructure through three questions:
How concentrated is it?
How critical is it?
How long does substitution take?
Timing exposes something those questions miss.
All three can produce relatively reassuring answers while the underlying exposure remains severe.
Because they describe the infrastructure.
They don't describe the organisation depending on it.
That requires another question:
Who owns the dependency?
Whose budget?
Whose contract?
Whose job description?
Without an answer, even a technically solvable problem can remain open for decades.
Sometimes the weakest layer in a complex system isn't the one that takes longest to replace.
It is the one everyone assumes somebody else is responsible for.
THRIVE IN CHAOS
Signal Over Noise
Analysis → Forecast → Recommendations
Signal → Meaning → Action → Stability
